Cyber-readiness: Meeting CMMC mandates

Government contractors must comply with the new Cybersecurity Maturity Model Certification (CMMC) program from the Department of Defense (DoD) and its standards to maintain existing contracts and win new ones.

If you’re preparing to get CMMC certification, you can use penetration tests, enterprise risk assessments and updates to incident response plans to help you prepare.

CMMC requirements for federal government contractors

The date for implementation is uncertain, but the DoD could begin implementing CMMC standards as soon as May 2023. However, it is possible that the date could be delayed until 2025.

Whenever implementation begins, contractors will need a DoD-approved CMMC contract clause in your agreements for the DoD’s new product and service acquisitions.

There are different levels of CMMC certification, and you’ll have to keep your certification at that level throughout the contract’s life, said HORNE Account Specialist Sarah Duncan.

“Many people I talk to think that 2025 is so far away. But it’s important to remember that the CMMC is based on a maturity model,” Duncan said. “It’s vital that you put cybersecurity processes and controls in place to meet the CMMC at least six months before that date.

“We’re helping companies do the readiness work now, and we’re finding that companies have a lot of remediation to do. That could take a while. We want to make sure no one is missing out on these big contracts they have,” she said.

“The CMMC standard is already showing up in requests for proposals as a bonus,” she said. “So, you can benefit from CMMC certification as you respond to RFPs and compete for DoD contracts.

“The CMMC standard affects many organizations, from major weapons manufacturers to construction companies that work at military bases and hospitals,” she added. “You may not even realize that applies to you.”

Is CMMC required for your business?

If you fulfill contracts for the DoD, you should find out now whether CMMC certification is a mandate for your business. CMMC certification counts on your adherence to the highest standards for cybersecurity controls, policies and procedures.

So, acquiring CMMC certification protects the revenues you make from DoD contracts and helps to ensures that you are equipped for potential attacks.

“There is speculation that the CMMC will apply to an increasing number of federal and even state contracts,” Duncan said, “making it a more significant mandate than we thought.”

Planning ahead

HORNE is a CMMC-registered practitioner organization (CMMC RP), advising and consulting with companies preparing to meet the CMMC standard, said Duncan. With HORNE penetration tests, enterprise risk assessments and consultations you can meet get CMMC certification.

Contact us today to find out how HORNE can help with your CMMC requirements.

READ MORE OF OUR LATEST INSIGHTS

SEE AROUND CORNERS.
INDUSTRY EXPERTISE DELIVERED.

More Insights

Six things you need to know about Google Analytics 4

Google Analytics 4 is the next generation of Google Analytics. This is not simply a new version; it’s a new way to track and present data....

READ MORE

Tips to get the most out of Google’s Helpful Content Update

Change is coming faster than ever. Every week, I search for the meaning of some new acronym that impacts our business processes. As someone who...

READ MORE

Bridging the Gap: Capturing knowledge before it walks out the door

By 2030, all baby boomers will be 65 or older. Not to mention that many Gen Xers — or those born between 1965 and 1980 — are now in their 50s....

READ MORE

Healthcare leaders need to be ‘aggressively urgent’

The healthcare industry is in a state of emergency today. In an industry where change notoriously happens gradually at best, leaders should change to...

READ MORE

How companies combat software insecurities

In most companies, developers are focused on meeting project deadlines, and that often leads to applications that are insecurely coded. Custom...

READ MORE

Web applications remain biggest threat to cybersecurity

One of the biggest threats facing organizations related to cybersecurity involves web application security. Organizations continue to use...

READ MORE

Talk to an expert today.